Scope chapter quiz

Quiz

Scope chapter quiz

Pick the answer that best matches the methodology.

A confirmed compromise of a system processing payment card data is detected. The technical investigation will take days. What does Scope require the analyst to do about timing?

An alert looks like phishing-driven intrusion. What is the typical historical window for the investigation?

An alert on a build-pipeline service account smells like possible supply-chain compromise. What historical window does Scope set?

The Subject phase identified seven identities connected to the alert. How many should be primary in scope?

Alert and Subject both lean benign on a developer-workstation alert, but the user's account can reach a dozen other systems. How does Scope draw the boundary?

An investigation needs in-app activity from a SaaS platform, but the SOC only has authentication logs and gross API metrics. What does Scope require?

A hospital SOC confirms a compromised workstation had access to systems holding PHI. When does HIPAA's 60-day individual-notification clock start?

During Scope, the analyst confirms that a compromised account assumed a cloud role during the investigation window. The decision-tree response is...

Scope confirms a compromised identity can reach systems inside the cardholder data environment (CDE). What does the methodology require?

A US SOC investigates a compromised account belonging to an employee in Germany, with the relevant logs stored in an EU region. What does Scope's sovereignty boundary require?

The Scope handoff to Uncover should include investigative questions. Why?

Need a nudge?

Think about what makes the difference between focused triage and unstructured exploration.

Next up

Transition to Uncover

Continue